First published: Mon Sep 12 2016(Updated: )
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =5.2.0 | |
Cisco FireSIGHT System Software | =5.2.0.1 | |
Cisco FireSIGHT System Software | =5.2.0.2 | |
Cisco FireSIGHT System Software | =5.2.0.3 | |
Cisco FireSIGHT System Software | =5.2.0.4 | |
Cisco FireSIGHT System Software | =5.2.0.5 | |
Cisco FireSIGHT System Software | =5.2.0.6 | |
Cisco FireSIGHT System Software | =5.2.0.8 | |
Cisco FireSIGHT System Software | =5.3.0 | |
Cisco FireSIGHT System Software | =5.3.0.1 | |
Cisco FireSIGHT System Software | =5.3.0.2 | |
Cisco FireSIGHT System Software | =5.3.0.3 | |
Cisco FireSIGHT System Software | =5.3.0.4 | |
Cisco FireSIGHT System Software | =5.3.0.5 | |
Cisco FireSIGHT System Software | =5.3.0.6 | |
Cisco FireSIGHT System Software | =5.3.0.7 | |
Cisco FireSIGHT System Software | =5.3.1 | |
Cisco FireSIGHT System Software | =5.3.1.1 | |
Cisco FireSIGHT System Software | =5.3.1.2 | |
Cisco FireSIGHT System Software | =5.3.1.3 | |
Cisco FireSIGHT System Software | =5.3.1.4 | |
Cisco FireSIGHT System Software | =5.3.1.5 | |
Cisco FireSIGHT System Software | =5.3.1.7 | |
Cisco FireSIGHT System Software | =5.4.0 | |
Cisco FireSIGHT System Software | =5.4.0.1 | |
Cisco FireSIGHT System Software | =5.4.0.2 | |
Cisco FireSIGHT System Software | =5.4.0.3 | |
Cisco FireSIGHT System Software | =5.4.0.4 | |
Cisco FireSIGHT System Software | =5.4.0.5 | |
Cisco FireSIGHT System Software | =5.4.0.6 | |
Cisco FireSIGHT System Software | =5.4.1 | |
Cisco FireSIGHT System Software | =5.4.1.2 | |
Cisco FireSIGHT System Software | =5.4.1.3 | |
Cisco FireSIGHT System Software | =5.4.1.4 | |
Cisco FireSIGHT System Software | =6.0.0 | |
Cisco FireSIGHT System Software | =6.0.0.1 | |
Cisco FireSIGHT System Software | =6.0.1 | |
Cisco FireSIGHT System Software | =6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6394 is considered a medium severity vulnerability due to its potential for session hijacking.
To mitigate CVE-2016-6394, upgrade the Cisco Firepower Management Center or FireSIGHT System Software to the latest version following Cisco's security advisory.
CVE-2016-6394 can lead to session fixation attacks, allowing remote attackers to hijack user sessions.
Affected versions of Cisco FireSIGHT System Software range from 5.2.0 to 6.1.0, including various updates within those major versions.
Yes, CVE-2016-6394 can potentially allow attackers to compromise user credentials by taking control of an active web session.